WordPress 的 WP File Download 插件在所有版本中(包括 6.3.8 及之前)均存在目录遍历漏洞,攻击入口为 参数。该漏洞允许拥有 Subscriber(订阅者)及以上权限的已认证攻击者读取服务器上任意文件的内容,而这些文件可能包含敏感信息。 具体攻击流程如下: 1. 拥有 Subscriber 权限的已认证攻击者首先通过未受保护的文件保存处理程序( handler)篡改 后置元数据值(post-meta value)。 2. 随后,流式传输端点(streaming endpoint)在 钩
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| JoomUnited | WP File Download | 0 ~ 6.3.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet